Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation indicates capabilities to read conversation exports, write results to workspace files, inspect environment variables, and optionally send data over the network, yet the metadata declares no corresponding permissions. This creates a transparency and consent problem: users and policy systems may not realize the skill can access local data and exfiltrate conversation content to external APIs.
